Test under sustained pressure
Operations run continuously rather than within a fixed window, so controls, people and processes are exercised the way a persistent adversary would exercise them
Continuous Adversary Operations Service (CAOS)
A persistent, objective-driven adversary simulation program. Senior operators run attacks against your environment year-round, in cycles, with findings logged in real time.
CAOS is a persistent, objective-driven adversary simulation program delivered by a dedicated team of senior operators. They run attacks against your environment throughout the year, using the tactics, techniques and procedures real adversaries employ against your sector, testing technical controls, people and processes under sustained pressure.
Reports follow each cycle, documenting results, observations, recommendations and improvements since previous cycles. Key operational activity is logged in real time on HackTrack, and your security team is given access once an execution cycle completes.
Operations run continuously rather than within a fixed window, so controls, people and processes are exercised the way a persistent adversary would exercise them
New systems, new exposure and completed remediation are tested as they appear, instead of waiting for the next annual assessment
Where an objective is reached without detection, operators can deliberately trigger an alert so the security team runs its response process for real
Each cycle report records observations and improvements since the previous cycle, and earlier test cases can be replayed to check whether detection has improved
CAOS suits organisations that already run detection and response and want it tested continuously. A SOC operating normally during operations is a prerequisite, because deliberately suppressing detection invalidates the result for that period.
CAOS fits when
Four phases, repeating. Each iteration begins by agreeing what the next cycle should prove.
Every cycle produces a plan, a report and two debriefs, with HackTrack tracking findings in between:
Continuous
Real-time findings tracking
Per cycle
Roughly every two months
Roughly every two months
Per cycle, up to two a year
Per cycle, up to two a year
Per cycle, up to two a year
A CAOS program is delivered by a named Lead and Specialist who stay with it for its duration, so the team builds and keeps a detailed understanding of your environment. Where a cycle needs depth in a particular domain, such as mobile, wireless, cloud-native attack paths, thick client or hardware and IoT, the relevant specialist joins the core team for that phase.
SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. The long-running nature of CAOS lets the team adapt as trending and bleeding-edge techniques emerge, pivoting when an opportunity appears rather than waiting for the next engagement.
CREST ANZApproved company Individual credentials across our team include
A red team engagement measures your defences within a fixed window. CAOS runs year-round in cycles, so changes to the environment and the fixes made after each cycle are tested as they happen. Cycles are not time-boxed; they close when the objectives are met, sufficient effort has been spent, or a high-severity incident means the activity must be disclosed.
Only the Control Group: a small group of senior staff with the business knowledge and seniority to make risk-based decisions. Keeping the knowledge there is what makes the test of detection and incident response realistic.
Respond as though it were real. The Control Group can deconflict through the primary channel, or the emergency channel when urgent. If operators are evicted they use redundant access, and if removed entirely they attempt to breach again unless the Control Group grants an assumed breach concession.
SilentGrid's platform for capturing operator logs, indicators of compromise and the techniques used during a cycle. Your instance holds the data from every cycle and purple team. Key techniques are visible to the Control Group during a cycle, and the full data set opens to your security team once the report is delivered, searchable and annotatable.
Yes. Objectives are set in the preparation workshop, and at each checkpoint the Control Group shapes the next push. A cycle can also be run as an intelligence-led exercise against a specific threat, or as a dedicated purple team.
Ready to run it continuously?
Tell us which business services matter most, and we will scope the first cycle around them.
Onboarding begins with a workshop that defines the objectives, the Control Group and the rules of engagement, and produces a cycle execution plan for approval before any operation starts.